AZ-305 Design infrastructure solutions Practice Question
Your company has an Azure subscription with multiple virtual networks connected via VNet peering. You need to design a solution to allow VMs in different peered VNets to resolve each other's private IP addresses using custom DNS suffixes. The solution must minimize administrative overhead. What should you implement?
⚠ Common exam trap
Many exam-takers assume custom DNS servers or Azure Firewall DNS proxy are needed for custom DNS suffixes, but Azure Private DNS Zone with auto-registration provides a fully managed, zero-maintenance solution for private DNS resolution across peered VNets.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an Azure Private DNS Zone linked to each VNet with auto-registration enabled.
Azure Private DNS Zone with auto-registration enables VMs in peered VNets to resolve each other's private IP addresses using custom DNS suffixes without deploying or managing custom DNS servers. When auto-registration is enabled, Azure automatically creates and updates A records for VMs in the linked VNet, and VNet peering propagates DNS resolution across peered VNets. This minimizes administrative overhead because no manual DNS server configuration or VM-level DNS suffix updates are needed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploy custom DNS servers on Azure VMs and configure VNets to use those servers.
Why it's wrong here
Deploying custom DNS servers on Azure VMs introduces significant administrative overhead because you must manually create and manage DNS records, implement high availability for the DNS service, and patch/update the underlying VMs. Since these servers also reside in the VNet, you need conditional forwarding and careful IP configuration, and they cannot take advantage of Azure’s automatic registration capabilities. Unlike Azure Private DNS Zones, custom DNS servers require ongoing operational effort and do not natively integrate with VNet topology or VM lifecycle events.
- ✗
Configure Azure DNS to use a custom domain name and update each VM's DNS suffix.
Why it's wrong here
Azure DNS as a service is designed for hosting public DNS zones and resolving internet-facing domain names, not for resolving private IP addresses of VMs inside a VNet. Simply applying a custom domain suffix to each VM does not create any A records or enable name resolution; the VMs still rely on Azure's internal DNS or a configured DNS server. For private name resolution across peered VNets, you must use Azure Private DNS Zones with VNet links, which Azure DNS does not provide in its public zone offering.
- ✗
Use Azure Firewall as a DNS proxy with custom DNS settings.
Why it's wrong here
Azure Firewall's DNS proxy is specifically for outbound traffic—it forwards DNS queries from virtual networks to an upstream DNS server, typically for resolving internet or on-premises names. It does not act as an authoritative or caching DNS server for internal VM hostnames, nor does it generate or manage records for resources in a VNet. Because it lacks zone management, auto-registration, and VNet-link integration, it cannot resolve VM hostnames across peered VNets and therefore is not a substitute for Azure Private DNS Zones.
- ✓
Create an Azure Private DNS Zone linked to each VNet with auto-registration enabled.
Why this is correct
Creating an Azure Private DNS Zone and linking it to each VNet with auto-registration enabled provides fully managed, automatic name resolution for VMs across the entire peered network topology. When auto-registration is turned on, Azure automatically creates and maintains A records for every VM as they are generated or deleted, eliminating manual record management. By linking the zone to all VNets involved in peering, nodes in any linked VNet can resolve each other's hostnames using the same private DNS namespace, making this the correct, scalable, and administration-free solution.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.